CVE-2024-27459Stack-based Buffer Overflow in Openvpn

Severity
7.8HIGHNVD
EPSS
5.4%
top 9.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 8
Latest updateMar 13

Description

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDopenvpn/openvpn2.6.02.6.10+1
CVEListV5openvpn/openvpn_gui2.6.9 and earlier

🔴Vulnerability Details

2
GHSA
GHSA-f6v5-hjxr-p24j: The interactive service in OpenVPN 22024-07-08
CVEList
CVE-2024-27459: The interactive service in OpenVPN 22024-07-08

📋Vendor Advisories

2
CISA ICS
Siemens SINEMA Remote Connect Client2025-03-13
Debian
CVE-2024-27459: openvpn - The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send ...2024

🕵️Threat Intelligence

1
Microsoft
Chained for attack: OpenVPN vulnerabilities discovered leading to RCE and LPE2024-08-08